It becomes a question of who to trust. In most cases I trust a binary
built by Debian more than I would a source tarball or a git checkout.
Large public code bases like Debian and the GNU toolset are now constantly getting hit by "audit kiddies" who slam the repositories with AI tools just to get their name on a CVE. Anything that doesn't belong in there is going to get found pretty quickly. Seems like every week we read a story "security issue that's been in there for ten years has been uncovered"